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CN ■ Abstract 

^ | We give a semantics to iterated update by a preference relation on possible 

■ developments. An iterated update is a sequence of formulas, giving (incomplete) 

information about successive states of the world. A development is a sequence of 
models, describing a possible trajectory through time. We assume a principle of 
inertia and prefer those developments, which are compatible with the information, 
and avoid unnecessary changes. The logical properties of the updates defined in 
this way are considered, and a representation result is proved. 
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1 Introduction 



> . 

^ ■ 1.1 Overview 

^ ■ We develop in this article an approach to update based on an abstract distance or ranking 
function. An agent has (incomplete, but reliable) information (observations) about a 
changing situation in the form of a sequence of formulas. At time 1, aq holds, at time 2, 
a 2 holds, . . . ., at time n, a n holds. We are thus in a situation of iterated update. The 
agent tries to reason about the most likely outcome, i.e. to sharpen the information a n by 
plausible reasoning. He knows that the real world has taken some trajectory, or history, 
that can be described by a sequence of models < mi, . . . ., m n >, where mi \= on (remember 
the observations were supposed to be reliable). We say that such a history explains the 
observations. For his reasoning, he makes two assumptions: First, an assumption of 
inertia: histories that stay constant are more likely than histories that change without 
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necessity. For instance, if n = 2, and ol\ is consistent with a 2 , mi \= a.\ A «2> m 2 h= ^2) 
then the history (mi, mi) is preferred to the history (m 1 ,m 2 ). We do NOT assume that 
(mi, mi) is more likely than some (777.3,777,2), i.e. we do not compare the cardinality of 
changes, we only assume "sub-histories" to be more likely than longer ones. Second, 
the agent assumes that histories can be ranked by their likelihood, i.e. that there is 
an (abstract) scale, a total order, which describes this ranking. These assumptions are 
formalized in Section 1.4. 

The agent then considers those models of a n as most plausible, which are endpoints of 
preferred histories explaining the observations. Thus, his reasoning defines an operator [ j 
from the set of sequences of observations to the set of formulas of the underlying language, 
s.t. [a u ,at n ] \= a n . 

The purpose of this article is to characterize the operators [ ] that correspond to such 
reasoning. Thus, we will give conditions for the operator [ ] which all operators based 
on history ranking satisfy, and, conversely, which allow to construct a ranking r from the 
operator [ ] such that the operator [ ] r based on this ranking is exactly [ ]. The first part 
can be called the soundness, the second the completeness part. 

Before giving a complete set of conditions in Section 3, we discuss in Section 2 some logical 
and intuitive properties of ranking based operators, in particular those properties which 
are related to the Alchourron, Gardenfors, Makinson postulates for theory revision, or to 
the update postulates of Katsuno, Mendelzon. In Section 3, we give a full characterization 
of these operators. We start from a result of Lehmann, Magidor, Schlechta on distance 
based revision, which has some formal similarity, and refine the techniques developed 
there. 

In the rest of this section, we first compare briefly revision and update, and then emphasize 
the relevance of epistemic states for iterated update, i.e. that belief sets are in general 
insufficient to determine the outcome of our reasoning about iterated update. We then 
make our approach precise, give some basic definitions, and recall the AGM and KM 
postulates. 

1.2 Revision and Update 

Intuitively, belief revision (also called theory revision) deals with evolving knowledge about 
a static situation. Update, on the other hand, deals with knowledge about an evolving 
situation. It is not clear that this ontological distinction agrees with the semantical and 
proof-theoretic distinction between the AGM and the KM approaches. In this paper, the 
distinction between revision and update must be understood as ontological, not as AGM 
vs. KM semantics or postulates . 

In the case of belief revision, an agent receives successively different information about 
a situation, e.g. from different sources, and the union of this information may be in- 
consistent. The theory of belief revision describes "rational" ways to incorporate new 
information into a body of old information, especially when the new and old information 
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together are inconsistent. 

In the case of update, an agent is informed that at time t, a formula <p held, at time t' <p' , 
etc. The agent tries, given this information and some background assumptions (e.g. of 
inertia: that things do not change unless forced to do so) to draw plausible conclusions 
about the probable development of the situation. This distinction goes back to Katsuno 
and Mendelzon ||. 

Revision in this sense is formalized in Lehmann, Magidor and Schlechta |§, elaborated 
in 0. The authors have devised there a family of semantics for revision based on min- 
imal change, where change is measured by distances between models of formulae of the 
background logic. More precisely, the operator defined by such functions revises a belief 
set T according to a new observation a by picking the models of a that are closest to 
models of T. Such revision operators have been shown to satisfy some of the common 
rationality postulates. Several weak forms of a distance function ( "pseudo- distances" ) 
have been studied in [7], and representation theorems for abstract revision operators by 
pseudo-distances have been proved. Since, in the weak forms, none of the notions usually 
connected with a distance (e.g. symmetry, the triangle inequality) are used, such pseudo- 
distances are actually no more than a preference function, or a ranked order, over pairs 
of models. 

In the present article, we consider a setting that intuitively has an ontology of update. It 
sets a single belief change system for all sequences of observations. All pseudo-distances 
are between individual models, as in the semantics proposed in ||. But, where Katsuno 
and Mendelzon's semantics takes a "local" approach and incorporates in the new belief set 
the best updating models for each model in the old belief set, we take a "global" approach 
and pick for the updated belief set only the ending models of the best overall histories. 
As a result, our system validates all the AGM postulates, and not all the KM ones. The 
introduction of an update system which follows the AGM postulates for revision may have 
some interesting ontological consequences, but these will not be dealt with in this work. 



The formal definitions and assumptions are to be found in Definitions O, |1.2| , 1.3, 
and Assumption 1.1. We prove a representation theorem for update operators based 
on rankings of histories, similar to those in ]/]]. Note that the approach taken here is 
more specific than that of [fTOfl , which considers arbitrary (e.g. not necessarily ranked) 
preference relations between histories. 



1.3 Epistemic States are not Belief Sets 

The epistemic state of an agent, i.e., the state of its mind, is understood to include 
anything that influences its actions, its beliefs about what is true of the world, and the 
way it will update or revise those beliefs, depending on the information it gathers. The 
belief set of an agent, at any time, includes only the set of propositions it believes to 
be true about the world at this time. One of the components of epistemic states must 
therefore be the belief set of the agent. One of the basic assumptions of the AGM theory 
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of belief revisions is that epistemic states are belief sets, i.e., they do not include any other 
information. At least, AGM do not formalize in their basic theory, as expressed by the 
AGM postulates, any incorporation of other information in the belief revision process. In 
particular an agent that holds exactly the same beliefs about the state of the world, at 
two different instants in time is, at those times, in the same epistemic state and therefore, 
if faced with the same information, will revise its beliefs in the same way. Recent work 
on belief revision and update has shown this assumption has very powerful consequences, 
not always welcome 0, 0], 0. Earlier work on belief base revision (see e.g. ||) expresses 
a similar concern about the fundamentals of belief revision. 

We do not wish to take a stand on the question of whether this identification of epistemic 
states with belief sets is reasonable for the study of belief revision, but we want to point 
out that, in the study of belief update, with its natural sensitivity (by the principle of 
inertia) to the order in which the information is gathered, it is certainly unreasonable. 
This is illustrated by the following observation: Let (j) an d if> be different atomic, i.e. 
logically independent, formulas. First scenario: update the trivial belief set (the set of 
all tautologies) by <fi, then by tjj, then by -xf> V -itf). Second scenario: update the trivial 
belief set by i/j, then by (p, then by -xj) V We expect different belief sets: we shall 
most probably try to stick to the piece of information that is the most up-to-date, i.e., ifi 
in the first scenario and in the second scenario. But there is no reason for us to think 
that the belief sets obtained, in both scenarios, just before the last updates, should be 
different. We expect them to be identical: the consequences of </> A ip. The same agent, 
in two different epistemic states, updates differently the same beliefs in the light of the 
same information. 

1.4 Preferred History Semantics 

We now make our approach more precise. The basic ontology is minimal: The agent 
makes a sequence of observations and interprets this sequence of observations in terms of 
possible histories of the world explaining the observations. 

Assume a set £ of formulas and a set U of models for C Formulas will be denoted by 
Greek letters from the beginning of the alphabet: a, (3 and so on, and models by m, n, 
and so on. We do not assume formulas are indexed by time. An observation is a consistent 
formula. (We assume observations to be consistent for two reasons: First, observations 
are assumed to be reliable; second, as we work with histories made of models, we need 
some model to explain every observation. Working with unreliable information would be 
the subject of another paper.) Observing a formula means observing the formula holds. 
A sequence of observations is here a finite sequence of observations. Sequences of ob- 
servations will be denoted by Greek letters from the end of the alphabet: a, r and 
concatenation of such sequences by •. Notice the empty sequence is a legal sequence of 
observations. We shall identify an observation with the sequence of observations of length 
one that contains it. What does a sequence of observations tell us about the present state 
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of the world? 

A history is a finite, non-empty sequence of models. Histories will be denoted by h, f, 
and so on. 

Definition 1.1 A history h — (m , . . . , m n ) explains a sequence of observations 
r = (cto, . . . , ctfe) iff there are subscripts < io < %\ < . . . < i\. < n such that for any j, 
< j < k, |= OLj . 

Thus, a history explains a sequence of observations if there is, in the history, a model that 
explains each of the observations in the correct order. Notice that n is in general different 
from k, that many consecutive i/s may be equal, i.e., the same model may explain many 
consecutive observations, that some models of the history may not be used at all in the 
explanation, i.e., I, < I < n may be equal to none of the i/s, and that we do not require 
that jk be equal to n, or that j be equal to 0, i.e., there may be useless models even at the 
start or at the end of a history. Note also that if h explains a sequence a of observations, 
it also explains any subsequence (not necessarily contiguous) of a. 

The set of histories that explain a sequence of observations give us information about the 
probable outcome. Monotonic logic is useless here: if we consider all histories explaining 
a sequence of observations, we cannot conclude anything. It is reasonable, therefore to 
assume the agent restricts the set of histories it considers to a subset of the explaining 
histories. 

We shall assume the agent has some preferences among histories, some histories being 
more natural, simpler, more expected, than others. A sequence of observations defines 
thus a subset of the set of all histories that explain it: the set of all preferred histories that 
explain it. This set defines the set of beliefs that result from a sequence of observations: 
the set of formulas satisfied in all the models that may appear as last elements of a 
preferred history that explains the sequence. The beliefs held depend on the preferences, 
concerning histories, of the agent. The logical properties of update depend on the class 
of preferences we shall consider. 

Formally, one assumes the agent's preferences are represented by a binary relation < on 
histories. Intuitively, h < f means that history h is strictly preferred, e.g. strictly more 
natural or strictly simpler, than history /. Note that our relation is on histories, not on 
models. We may now define preferred histories. 

Definition 1.2 A history h is a preferred history for a sequence a of observations iff 

• h explains a 

• there is no history h! that explains a such that h! < h. 

In this work two assumptions are made concerning the preference relation <. First, we 
assume < is a strict modular, well-ordering, i.e., < is irreflexive, transitive, if h < h', then 
for any /, either h < f or / < h! and there is no infinite descending chain. Secondly, we 
assume that partial histories (i.e., sub-histories) are preferred over (longer) histories: 
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Assumption 1.1 If h = (m , . . . , m n ) and h! = (mj , . . . , mj k ) , for 
< jo < j\ < ■ ■ ■ < jk < n and < k < n, then h! < h. 

For instance, h' = (m 2 , m 4 ) is preferred to h = (mi, m.2, m 3 , 777,4). 

This assumption is justified both by an epistemological concern: simpler explanations are 
better, and by an assumption of inertia concerning the way the universe evolves: things 
tend to stay as they are. This assumption, in a finite setting, trivializes the well-ordering 
assumption. 

Finally, we formally define our operator [ ]: 

Definition 1.3 After a sequence a of observations, the agent holds the beliefs [a], defined 
by a G [a] iff for every model m and every history h, if h is a preferred history explaining 
a and m is the last element of h, then m\= a. 

Notice that, since histories are non-empty, this definition always makes sense. 
The remainder of this paper will show that the assumptions above have far reaching 
consequences: they are strong assumptions. Our purpose is indeed to look for a powerful 
logic, not for the minimal logic that agrees with any possible ontology. 



1.5 Basic Definitions and Notation 

We are dealing here only with finite and complete universes, so theories have logically 
equivalent formulas (and vice versa), and are isomorphic to sets of models, and we will 
use them in these senses interchangeably. We will see sequence concatenation also as an 
outer product (with respect to concatenation) of sets of histories. For technical reasons, 
most of the discussion will relate to sets of models. An exception, for easier readability 
and comparison with the AGM and KM conditions is Section 2. We do not consistently 
differentiate singletons from the members that comprise them, because it is always clear 
from context which of them we are referring to. 
A theory, or belief set, will be a deductively closed set of formulas. 

For the convenience of the reader, we recall the AGM postulates for belief revision, (see 
e.g. 0), and the Katsuno-Mendelzon postulates for update (see e.g. 0): 

(K * 1) K * a is a deductively closed set of formulas. 

(K * 2) a G K * a. 

(K * 3) K * a C Cn(K,a). 

(K * 4) If £ K, then Cn(K, a) C K * a. 

(K * 5) If K * a is inconsistent then a is a logical contradiction. 

(K * 6) If |= a <-» /3, then K * a = K * (3. 

(K * 7) K * a A (3 C Cn(K *a,/3). 

(K * 8) If -./J £ K * a, then Cn(K * a, (3) C K * a A j3. 

(ui) |= W> •/*)-/*■ 
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(U2) If (= ip -»• fa then (= (-0 • //) V- 

(U3) If both t/> and /i are satisfiable, then so is -0 • \x. 

(U4) If |= <-> -02 and [= fa <-+ fa, then |= (ipx • fa) <-> (ip 2 • A^)- 

(U5) \=((tf>-fi)A<l>)^^-(jiA(f>)). 

(U6) If f= (V> • A*i) -> A*2 and (= (V> • // 2 ) -> fa, then [= • fa) «-> (ip ■ fa). 
(U7) If ^ is complete, then |= (-0 • a/i) A (if) ■ fa) — > (if) ■ (fa V fa)). 
(U8) h ((V>i V ^2) • aO <-> (</>i • n) V (^2 ■ n). 

The following is a slight reformulation of the AGM postulates in the spirit of Katsuno- 
Mendelzon, taken from |7|. We consider here a symmetrical version, in the sense that K 
and a can both be theories, and simplify by considering only consistent theories. 

(*0) If h T <-> S, |= V <-> 5', then T * V = S * S' , 
(*1) T * T' is a consistent, deductively closed theory, 
(*2) T" C T * T', 

(*3) If TUT' is consistent, then T*T' = Cn(T U T'), 

(*4) If T * T' is consistent with T", then T * (V U T") = Cn((T * T) U T"). 
Finally, we recall the definition of a pseudo-distance from 0. 

Definition 1.4 

d : U x U Z is called a pseudo-distance on U iff Z is totally ordered by a relation < . 



2 Some Important Logical Properties of Updates 

A number of logical properties of the operator [ ] will now be described and discussed. 
The reasons why those properties hold are varied: some depend on very little of our as- 
sumptions, some on almost all of them. We shall try to make the appropriate distinctions. 

Lemma 2.1 For any a, [a] is a theory. 

This property is analogous to AGM's (K * 1) and is implicit in Katsuno-Mendelzon's 
presentation H. This depends only on the fact that Definition 173 defines [a] as the set 



of all formulas that hold for all the models in a given set. Indeed, this is a property that 
is expected to hold by the structure of belief sets, not by the definition of explanation or 
certain properties of the preference relation. 



The following properties hold by the definition of explanation, i.e., Definition [LT 



Lemma 2.2 If a and a' are logically equivalent, then for any sequences a , r: 
[a ■ a ■ t] — [a • a' - r] . 

This property is analogous to AGM's (K * 6) but notice that, there, it is needed only for 
the second argument of the revision operation, since it is implicit for the first, a theory. 
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It parallels (U4) in Katsuno-Mendelzon's ||. Lemma |272| follows from Definition that 
implies that the histories that explain a ■ a ■ r are exactly those that explain a ■ a' ■ r. 
The preferred histories are therefore the same. The next property is more original. 



Lemma 2.3 If (3 |= a, then for any sequences a, t: 
[a ■ a ■ P ■ t] = [a ■ (3 ■ t] = [<t ■ (3 ■ a ■ t}. 

This property has no clear analogue in the AGM or KM frameworks, but is closely related 
to (U2) of p. The first equation is property (CI) of Darwiche-Pearl's and (15) of ||. 
The second equation is a weakening of (14) of ||. Here we request a to be a logical 
consequence of (3, there we only asked that a be in [a ■ (3\. Lemma |2.3| is a consequence of 
the fact that the histories that explain a-(3-T,a-a-/3-r and a ■ (3 ■ a ■ r are the same. 

Corollary 2.1 For any sequence a, [a ■ true] = [a]. 

The next property deals with disjunction. 

Lemma 2.4 If 7 is a member both of [a ■ a ■ r] and [a ■ (3 ■ r], then it is a member of 
[a • a V f3 ■ t] . In other words 

[a ■ a ■ t) n [a ■ (3 ■ r] C [a ■ a V (3 ■ r). 

This property is similar to one half of (U8) of 0, and to a consequence of AGM's (K*7), 
as pointed out in |§, property (3.14): (K * A) n (K * B) C K * (A V B). 
Lemma [O] depends only on Definitions |0| and (L2], but does not depend on any properties 
of the preference relation. A history h that explains a ■ a V (3 ■ r explains a ■ a ■ r or 
a ■ (3 ■ t. A preferred history for a ■ a V (3 ■ r must therefore either be a preferred history 
for a ■ a ■ t (since any history explaining the latter explains the former) or preferred 
history for a ■ (3 ■ r. The next lemma is a strengthening of Lemma |2.4| , and it depends on 
the modularity of the preference relation. 

Lemma 2.5 The theory [a ■ a V f3 ■ r] is equal to [a ■ a ■ r], equal to [a ■ f3 ■ t] or is the 

intersection of the two theories above. 

This property is a weakening of (U8) of j5|, compare also to property (3.16) in H: K * 
(A V B) = K * A or K * (A V B) = K * B or K * (A V B) = (K * A) n (K * B). 
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Proof : A history h that explains a ■ a V (3 ■ r explains a ■ a ■ r or a ■ (3 ■ r. If all preferred 
histories for a ■ a V (3 ■ r explain a ■ a ■ r, then 

• any preferred history for a ■ a V (3 ■ r is a preferred history for a ■ a ■ r (other- 
wise there would be a strictly preferred history for a ■ a ■ r, but that explains 
a ■ a V (3 ■ r), and 

• any preferred history for a ■ a ■ r is a preferred history for o ■ a V (3 ■ r, otherwise 
there would be a strictly preferred history for a ■ a V (3 ■ r that satisfies a ■ (3 ■ r. 

In this case, [a ■ a V j3 ■ r] is equal to [a ■ a ■ r]. 

Similarly, if all preferred histories for a ■ a V (3 ■ r explain a ■ (3 ■ r, then [a • en V f3 ■ r] is 
equal to [a ■ (3 ■ r]. 

Let us assume, therefore, that some preferred histories for a ■ a V (3 ■ r explain a ■ a ■ r 
and that some explain a ■ (3 ■ r. By modularity of the preference relation, any preferred 
history for a ■ a ■ r is a preferred history for a ■ en V (3 ■ r. | 

The next properties follow from the assumption that sub-histories are preferred to more 
complete histories. Remark first that, if a history h explains a non-empty sequence a of 
observations but the last model of h does not satisfy the last observation of a, then there 
is a shorter (initial) sub-history of h that explains a. The history h cannot be, in this 
preferred history for a. 

Lemma 2.6 For any sequence a of observations and any formula a: a G [a ■ a}. 

This property is similar to AGM's (K * 2) and (Ul) of ||. In @, Friedman and Halpern 
question this postulate. Here, it finds a justification, grounded in our preference for 
shorter explanations. 

Lemma 2.7 For any sequence a of observations and any formulas a and (3, if 
^ [a ■ a], then [a ■ a ■ /?] = [a ■ a A j3\ — Cn([a • a], (3). 

This property is analogous to AGM's (K * 7) and (K * 8). 

Proof: We show that the preferred histories for a ■ a ■ (3 are exactly those preferred 
histories of a ■ a whose last element satisfies (3. First, clearly, any preferred history for 
a ■ a whose last element satisfies (3 explains a ■ a ■ (3 and is a preferred history for it. 
Secondly, since ->f3 ^ [a ■ a], there is a preferred history h for a ■ a whose last element 
satisfies (3. As we have just seen h is a preferred history for a ■ a ■ f3. Let / be a preferred 
history for a ■ a ■ (3. It explains a ■ a. If it were not a preferred history for a ■ a, there 
would be a history f < f that explains a ■ a. By modularity, we would have f'<h 
or h < f, which are both impossible. We conclude that / is a preferred history for a ■ a. 
But its last element satisfies (3, by Lemma |2.6| . 
We have shown that [a ■ a ■ (3} = Cn([a ■ a],{3). 

To conclude the proof, notice that, by the above, any preferred history for a ■ a ■ (3 explains 
a ■ a A (3 and that any history explaining a ■ a A (3 also explains a ■ a - (3. | 
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Corollary 2.2 If ->a £ [a], then [a ■ a] = Cn([a],a). 



This parallels AGM's (K * 3) and (K * 4). 

Proof: By Corollary |2.1| , [a] = [a ■ true]. By Lemma |2.7| , 

[a • true • a] = Cn([a ■ true], a) — [a ■ true A a]. 

By Corollary |2.1| and Lemma |2.3| Cn([cr], a) — [a ■ a]. | 

Our last property depends on well-foundedness, which is trivial in a finite setting. 



Lemma 2.8 For any sequence a, [a] is consistent. 



This parallels AGM's (K*5) and KM's (U3). This property depends on two assumptions. 
First we assumed observations were consistent formulas. It follows that any sequence of 
observations is explained by some history. By finiteness, if h explains a and h is not a 
preferred history for a, then there is a preferred history h! for a (in fact one such that 
h' < h). Therefore [a] is consistent. 



3 A Representation Theorem 
3.1 Introduction 

In Section 2, we have presented several logical properties of operators [ ] based on history 
ranking. In this Section, we will give a full characterization. We generalize here results 
about revision reported in J7J. We will first show that a straightforward generalization 
of the not necessarily symmetrical revision case fails already for sequences of length 3, 
and will then give a characterization for sequences of arbitrary finite length in Theorem 
3.2. A technical problem for the latter is that we have to work with "illegal" sets of 
histories, which do not correspond to sequences of sets of models. E.g. the set of sequences 
{(0, 0, 0), (0, 1, 1)} is not the product of any sequence of sets - {0} x {0, 1} x {0, 1} contains 
too many sequences. Our operator is, however, only defined for such sequences of sets. 
We use the idea of a patch, a cover of such sets of sequences by products of sequences of 
sets, to show our result. 

As mentioned before, we will want to work mainly with sequences of sets of models. Such 
sets are freely interchangeable with observations, and every sequence thereof also defines 
a set of histories. We would like the set of all explaining histories to be representable as 
a sequence of sets of models. Definition |1.1| allows the set of explaining histories to be 
infinite, and we will limit the sets of histories dealt with by an assumption strengthening 
Lemma [2.6| . While we do not assume full sub-history preference, we assume that a history 
explains a sequence of observations if they are of the same length, and the ith model in 
the history models the ith observation in the sequence. This assumption, like the Lemma, 
is justified by sub-history preference, with an implicit agreement that consecutive repeats 
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of a model in a history are merely another way to write that the model explains several 
observations. In other words, to make the formal phrasing and proof a little easier, we 
will write for each observation in the sequence a the model that explains it in the history 
h. A history hi containing h as a sub-history will not be preferable to h, and sub-histories 
of h are just represented as longer than they are. Intuitively, an assumption is made 
here that e.g. (mi, mi, m 2 ) and (mi, m 2 , m 2 ), both being representations of (mi, m^), are 
equally preferred, and are both considered better than (mi, m 2 , 772,3). This assumption is 
neither used nor needed in the theorem or its proof. We make no further assumption on 
the history-preference relation. 

Histories and sequences of observations of length or dimension 2 are closely parallel to the 
not necessarily symmetric case of 0. We first recall the corresponding representation 
result in Section 3.2. Then, we show that a simple generalization of this result fails 
already in the case of length 3 (Section 3.4). Finally, in Section 3.5, we prove a valid 
representation theorem for the general, n-dimensional case. 

3.2 The 2-D Representation Theorem 

First, let us quote a theorem characterizing the revision operators representable by a 
pseudo-distance function (Proposition 2.5 of The pseudo-distance mentioned here 

is actually no more than a preference relation over pairs of models (or histories of length 
2). The theorem deals with an operator | which revises a belief set by an observation, i.e., 
A I B is the belief set held by an agent who has held a belief set A, after observing B. 
Now, let X be a finite and complete universe (the set of possible models of the language). 
In such a universe, A and B are interchangeably formulas, theories and sets of models. 
Let V(X) designate the set of all non-empty subsets of X. 

Definition 3.1 An operation | : V(X) x V(X) — > V(X) is representable iff there is a 
pseudo- distance d : X x X — > Z such that 

A\B = {beB\3aeA such that Va' G A, b' G B, d(a, b) < d(a , &')}. 

Thus, intuitively, if A and B are sets, A \ B is the set of those elements of B, which are 
closest to the set A. By abuse of notation, if A and B are formulas, A \ B is the set of 
formulas valid in the set of those models of B, which are closest to the set of models of 
A. 

For this theorem, Lehmann, Magidor and Schlechta define a relation R\ on pairs from 
V(X) x V(X), which intuitively means "provably closer" or "provably preferable", i.e., 
assuming the underlying pseudo-distance exists, this relation represents information about 
it that may be deduced by examining the revision operation. For instance, if (A | (B U 
C)) fl B 7^ 0, B is provably at least as close to A, as C is to A. This information can 
only apply to the best-preferred pairs of models in the pairs of sets, so (A, B)R\(A', B') 
actually means we have evidence that the best pair of models in A x B is at least as 
preferable as the best pair in A' x B' . 
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Definition 3.2 Given an operation \ , define a relation R\ on pairs from V(X) x V(X) 
by: (A, B)R\(A' , B') iff one of the following two cases obtains: 

1. A = A' and (A \ (B U B')) n 5 ^ ; 

2. B = B' and {{A U A') \ B) ^ (A' \ B). 

In the rest of this subsection we shall write R instead of R\. As usual, we shall denote by 

R* the transitive closure of R. 

Now, we can quote the representation theorem: 

Theorem 3.1 An operation \ is representable iff it satisfies the four conditions below for 
any non-empty sets A, A', B, B' C X: 

1. {A | B) C B, 

2. {{A U A') \B)Q(A\B)U {A' \ B), 

3. If (A, B)R*(A, B'), then (A \ B) C (A | (B U B')), 

4. If (A, B)R*(A', B), then (A | B) C ((A U A') \ B) 

This is the strongest version of this theorem proven. Fixing the conditions of the theorem, 
the characterization grows stronger as the definition of R becomes narrower, as it then 
(possibly) puts less constraints on |. A weaker characterization (which is also valid) has 
R defined to be wider, as follows: 

Definition 3.3 We say the relation R\ holds iff at least one of the following cases obtains: 

1. AD A',BD B' => (A, B)R(A', B') 

2. (A\(BU B')) B)R(A, (B U B')) 

3. {{A U A') | B) j£ (A' | B) (A, B)R({A U A'), B) 

3.3 Ultimate Goal: The n-Dimensional Case 

We want to prove a theorem analogous to Theorem |3.1| that relates to strings of observa- 
tions of length n (instead of length 2, if we ignore the difference in role between a previous 
observation and a previous belief set), that is, we want to characterize representable op- 
erations [] : V(X) n ->V(X): 
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Definition 3.4 An operation [ ] : V(X) n — > V(X) is representable iff there is a totally 
ordered set Z (the order is <) and a function r : X n — > Z (that will be intuitively under- 
stood as a history ranking), such that, for any non-empty subsets A ± , ...A n C X , 

[A 1 ---A n } = 

{a n E A n | 3ai E A 1 ...a n - 1 E A^iVa^ E Ai...a! n E A n r(a 1 , a n ) < r(a[, a' n )} 

We will now see that this may not be achieved by straightforward generalization of the 
tight 2-dimensional characterization, even for just three dimensions. 

3.4 Simple Generalization is not Valid 

The first attempt at generalizing this theorem is held short at n — 3. Let us phrase the 
suggested theorem and disprove it, starting with a new definition for R: 

Definition 3.5 Given an operation [ ] , one defines a relation on triplets of non- 
empty subsets of X by: (A,B,C)R[j(A',B',C) iff one of the following cases obtains: 

1. A = A',B = B' and [A ■ B ■ (C U C')\ n C ^ 0. 

2. A = A',C = C and [A ■ (B U B') ■ C\ ± [A ■ B' ■ C}. 

3. B = B',C = C and [{A U A') ■ B ■ C] ^ [A' ■ B ■ C}. 

iFrom here on, unless otherwise stated, R stands for i?[ ] . Now, the suggested theorem: 

Suggested Theorem 3.1 An operation [ ] is representable iff it satisfies the six condi- 
tions below for any non-empty sets A, A', B, B', C, C C X: 

1. [A ■ B ■ C] C C. 

2. [A ■ (B U B') ■ C] C [A ■ B ■ C] U [A ■ B' ■ C\. 

3. [{A U A') ■ B ■ C] C [A ■ B ■ C] U [A' ■ B ■ C\. 

4. (A,B,C)R*(A',B,C) => [A-B-C] C [{AuA') ■ B ■ C}. 

5. (A, B, C)R*{A, B', C) => [A ■ B ■ C\ C [A ■ (B U B') ■ C] . 

6. (A, B, C)R*{A, B, C) => [A ■ B ■ C\ C [A ■ B ■ (C U C')\ . 

This theorem is not valid. 
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Proof: There is a counter-example, as follows: Let X = {0, 1} and n — 3. This seems to 
be the simplest n- dimensional case for n > 2. For convenience, we will write for {0}, 1 
for {1}, X for {0, 1}, and * for any of them. Define [ ] as follows: 

[*.*.0] =0 ; [*•*• 1] = 1; 
[0 • • X] = ; [0 • 1 • X] = 0; 
[1 • • X] = 1 ; [1 • 1 • X] = X; 
[0 • X ■ X] = ; [1 • X ■ X] = 1; 
[X • • X] = ; [X • 1 • X] = X; 
[X ■ X • X] = X. 

The cases where C = {0} and C = {1} are forced by condition |I]of the theorem, and are 
not very interesting. As for the case C = X, one may check for each two triplets that fall 
under the conditions of the theorem that it holds. The check is simplified by the fact that 



Definition [TS| gives no way to show that (A, B, C)R(A', B', C) when A C A' and B C B', 
and the fact that there is no valid union of sets of sequences of different cardinalities, 
unless one is contained within the other. The operator complies with all the conditions 
of Suggested Theorem |3T] . But suppose there is a ranking that defines [ ], we reach the 
following conclusions (using x -< y for xRy, and x -< y for xRy but provably ~^yR*x, and 
remembering that the conditions of the Suggested Theorem hold): 

(1-1-X) r< (0-1-X) 

by Definition p75] , case |^, 

(1-0-X) -< (1-1-X) 

by case ^| of Definition [37|, and negation of condition |^ of the Suggested Theorem, and 

(0-0-X) -< (1 -0-X) 

by case || of the definition of R and negation of condition § of the Suggested Theorem. 
Thus, the best history in {0} • {0} • X (which we know to be • • 0) would also be the 
single best history in X ■ X ■ X, but we find [X ■ X ■ X] = X instead, which means there 
really is no underlying ranking. | 

The next natural step is to use a definition more like Definition |3.3| in the generalized 
theorem. If R was defined as follows: 

Definition 3.6 We say the relation Rn holds iff any of the following cases obtains: 
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1. A^A',BD B', CDC (A, B, C)R(A', B\ C) 

2. [A ■ B ■ (C U C')] nC/^(AB, C)R(A, B,CU C) 

3. [A ■ (B U B') ■ C] ^ [A ■ B' ■ C] {A, B, C)R{A, B U B', C) 

4. [{A U A') ■ B ■ C] ^ [A' - B ■ C] {A, B, C)R{A U A', B, C) 

Then, for the operator defined in the counter-example, we could show that 
(1, 0, X)R(1, X, X)R(X, X, X)R(X, 0, X) 

but 

[1 • • X] ^ [X • • X] 

so the operator violates condition f|, and is thus not a counter-example. We have not 
been able to prove a representation theorem using Definition and believe it not to be 
valid. Yet, we have not found any counter-example. We have discovered (by computerized 
enumeration of the operators) that there are no counter-examples with n = 3 and | X |= 2, 
and the question whether it is valid for all n and | X |, and if not, for which n and | X | it 
is valid, remains open at this stage. 

3.5 An n-Dimensional Representation Theorem 
3.5.1 Patches 

We believe that for this theorem, we need a way to work around "illegal" sets of histories, 
i.e. such that are not sequences of sets of models. We call such sets "illegal" because, not 
being interchangeable with sequences of observations, our operator cannot be applied to 
them. For the technique used in this proof, it is especially regretful that for most sequences 
a, if we try to present a as a disjoint union of a "legal" sequence (say, a singleton) r with 
the rest of the histories in the sequence a \ r then the latter will be illegal. Instead, we 
use a family of legal sequences whose union is a \ r. As it complements r to a, we call 
this family a patch. 

Definition 3.7 Given a sequence A x ■ ■ ■ A n and a sequence A' x ■ ■ • A' n such thatWiA^ C A i} 
we define the patch to A 1 ■ ■ ■ A n from A' x • ■ ■ A' n to be the set of sequences comprised of all 
the sequences B\ - ■ ■ B l n for each i such that A\^ A i; where 

1. Vj + %, B) = A, 

2. B\ = Ai \ A[ 
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Let, for instance, n = 3, A := {0, 1} • {0, 1} ■ {0, 1}, A' := {0} ■ {0, 1} ■ {0}, then the patch 
to A from A' is {B 1 := {1} ■ {0, 1} ■ {0, 1}, B 3 : = {0, 1} ■ {0, 1} ■ {1}}. 
Note that the (disjoint) union of A' with (J; B l is equal to A. 

As with the definition of R\ , this definition is made as tight as possible to make the theorem 
stronger. We will see later that if we relax the definition a little, allowing many patches 
from A' to A by letting B\ be any set such that A\ U B\ = A iy our theorem will become the 



generalization of the weaker form of Theorem qJ] (the one using Definition |3.3|) . Notice 
also that Definition [T7| may be easily written in the language of formulae; we do not wish 
our basic concepts, or the phrasing of the representation theorem, to stray too far from 
our original problem domain. 



3.5.2 The Theorem 

With the new tool, the patch, we may define a new, more powerful relation of "provable 
preferability" . 

Definition 3.8 Given an operation [ }, define a relation Rn on sequences of length n of 
non-empty subsets of X by: ( A' x , A^_ x , C')R[]( Ax, Ai-lj C) iff one of the following 
cases obtains: 

1. ViAi C A[ and C C C. 

2. MiAi = A\, C'QC and [Ax--- A n -i • C] n C ^ 0. 

3. ViAi D A' i; C = C, {B\ ■ ■ ■ is the patch to Ax--- A n ^ x from A\ ■ ■ ■ A' n _ x , and 
one of the following holds: 

(a) alBl-'-B^-C] £ [Ax---A n _x-C] 

(b) [A l ---A^x-C}g[j i [Bt---B^ l -C} 

Now we are ready to phrase the representation theorem for the n-dimensional case: 

Theorem 3.2 An operation [ ] is representable iff it satisfies the three conditions below 
for any non-empty sets Ax, ...A„_i, CCI; 

1. [Ax---A n -x-C] QC, 

2. If ViA't C Ai and {B[--- B l n _ x } is the patch to Ax--- A n _ x from A[ ■ ■ ■ A' n _ t then 
[Ax---A^x-C}C[A' 1 ---A' n _ 1 -C}U[Ji[Bi---Bi l _ 1 -C} 

3. IfViA't C A it C C C and (A[ ■ ■ ■ A' n _ x ■ C')R*(Ax ■ ■ ■ A n _ x ■ C), then 
[A' 1 ---A' n _ 1 -C'} C [Ax---A n -x-C\. 
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Before proving this theorem, we note that when taking the more relaxed version (as 



mentioned above) of Definition 3/7, and taking Definition 3J3 to define R\, Theorem |3 
becomes the special case of Theorem with n = 2: Under these definitions, for any 
sets A and A', A' (or rather, the set comprised of it as a single sequence of length 1) is 
a patch to A U A' from A, so the concept of the patch coincides with union. When the 
patch has only one sequence (of one set) in it, then C\[B\ ■ C] = \J[B\ ■ C] = [B\ • C], and 



so the and [3b| of Definition |3_8] together become case y of Definition |3.3| . And 



finally, the conditions |3| and |] of Theorem |3.1| are expressed together as condition |3| of 



Theorem [3.2| . Note that condition 3 in Theorem |3.2| is essentially a loop condition. Let 



us now prove the more general theorem. 



Proof: For the proof of Theorem |37^, a number of lemmas will be needed. These lemmas 
will be presented when needed, and their proof inserted in the midst of the main proof. 
First, we shall deal with the soundness of the theorem, and then with the more challeng- 
ing completeness. 

Suppose, then, that | ] is representable. The ranking r of histories may be ex- 
tended to sequences of sets in the usual way, by taking the minimum over the sets: 
r(A 1 , ...,A n ) = min ai( zAi{ r ( a i, ■■■, a n)}- One may then write the equation defining repre- 
sentability as 

[A 1 --- A n _! ■ C] = {c G C | r(Ai, A n _ u {c}) = r(A u A n _ 1; C)} 



Let us now show that the three conditions of Theorem |3^ hold: 

Condition |T] is obvious. For Condition |2|, notice that, on one hand, 
Af-An-t = \J i {B\---B i n _ 1 }U(A' 1 ---A' n _ 1 ), and on the other hand, 
if r(d, a n -i, c) = r(A u A n _ l5 C), (a x , - • • , a n , c) e A" ■ ■ ■ A" n _ x ■ C" for some A", C", 
and A" ■ ■ ■ A" n ^ x ■ C" C Ay ■ ■ ■ A n _i ■ C then also r(oi, a„_i, c) = r(A'(, A£_ v C") and 
c G [A'{ ■ ■ ■ A" l _ l ■ G"\. For Condition |3] we need a little lemma: 

Lemma 3.1 For any non-empty sets A4, A^, C, C C X , 

(A[, C')R{A U An_x, C) r(A[, C) < r(A u A n _ u C) 



Proof: Let us consider the different cases of Definition |3.8| : 
Case |l] is obvious. 

In case ^ the negation of the consequence r(Ai, A n _i, C) < r(A[, A' n _ 1 , C) implies 
[Ay ■ ■ ■ A n _i • C] fl C = which is the negation of the assumption. 

Both sub-cases of case ^| rely on the reasoning used for Condition above: In case |3a| by 
assumption there exists c such that c G C\i[B\ ■ ■ ■ B l n _ x ■ C] but c G" [A\ ■ ■ ■ A n _i ■ C]. By 
the former, for each i there is a history (b\, • ■ ■ , b l n _ X) c), K- G Bj, with r(b\, ■ ■ ■ , b^^, c) 
minimal in B\ • ■ ■ B l n _ l ■ C, but by the latter, for none of these histories r(b\, ■ ■ ■ , b 1 n _ l , c) 
is minimal in Ay • ■ ■ A n _i ■ C . So the histories with r minimal in A% ■ ■ • A n _i ■ C have to 
be all members of A[ - ■ ■ A' n _ 1 • C which implies r(A[, A! n _ tl C) < r(A±, A„_i, C) as 
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needed. 

In case I3R by assumption there is at least one history that is one of the best in 



Ax ■ • • Ai-i ■ Cj but is not one of the best in (and thus not a member of) B\ ■ ■ ■ B % n _ x ■ C for 
any i. Hence this history is in A[ • • • A' n _x ■ C and r(A[, A' n _ tl C) < r(Ax, C) 
as needed. | 

We conclude that Condition |3] holds and the characterization is sound. 
For the completeness part, assume the operator [ ] complies with the conditions of Theo- 
rem p.2| . Using the Generalized Abstract Nonsense Lemma 2.1 of 0, extend R to a total 
preorder S satisfying 

xSy, ySx xR*y. (2) 

Let Z be the totally ordered set of equivalence classes of V(X) n defined by the 
total pre-order S. Define a function d : V(X) n — > Z to send a sequence of sub- 
sets Ax,...,A n to its equivalence class under S. We shall define r : X n — > Z by 
r(ax, On) == d({ai}, {a n }). While we aim to prove that r represents [ ], we will 
have to use d for the proof, d has the following obvious properties: 

{Ax, A n _x, C)R(A' 1 , A' n _ x , C) 

d(Ax, A»-i, C) < d(A' 1? CO, 1 j 

and, from Equation p|, 

A„_i, C) = d(A[, A' n _ 1 , C ) ... 
=> (Ax, .., A^-i, C)iTK, C). 1 J 

o? also has the less obvious property shown by the next lemma, which means it approxi- 
mates representation as far as the last argument is concerned: 

Lemma 3.2 For any Ax, A n ~x, C , 

d(Ax, Ai-i, C) = min ceC {d(Ax, A n ^, {c})} 

and 

[Ax--- A n _x ■ C] = {c e C | A n „x, {c}) = K-i, C)}. (5) 
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Proof: Suppose c G C, then (Aj., ...,Ai-i> C).R(Al, A n _ x , {c}) and from Equation | 
we get <i(A, A n _ 1 , C) < min c <z C {d(A x , A n _i, c)}. If moreover c 6 [A • ■ ■ Ai-i • C], 
then " [Ax • ■ ■ A*-i ■ C] n {c} ^ 0, 

and by Definition j3T8t part |], (Ah Ai-i> { c })^(Ai) Ai-i> C) and therefore 
<f(Ab An-i, c) = d(A x , A n _ x ,C). We have shown that the left hand side of Equa- 
tion ^| is included in the right hand side. 

Since [A x ■ ■ ■ Ai-i ■ C] is not empty, 3c G [A\ ■ ■ ■ Ai-i ■ C] and, by the previ- 
ous remark, d(A\, Ai-i) C) = d(A x , Ai-i ; c) and therefore we conclude that 

A^i, C) = min ceC {d{A x , A n _ x , c)}. 
To see the converse inclusion, notice that d(A x , A n _ x ,C) = d(A x , A n ^ x , c) 



implies (A x , A n _ x ,c)R k (A x , A n _ x ,C) and, by Property y of Theorem |3?2| , 
[Ai • • • A>-i • {c}] C [A • • • Ai-i • C] , so c G [ A • • • Ai-i ■ C] by Property [L] of the the- 
orem. | 

We now have to show that 

{c G C | 3ax, a n _i, si. Va^, a' n _ x , c' G C, r(ai, a„_i, c) < r(a' x , a^_ l5 c')} 
(where Vz a.j, G A)- 

To see that the right hand side is a subset of the left hand side, assume that a { G A;, c G C 
are such that for all G A, c' G C, r(ai, a n _i, c) < r(a' 1 , ajj_ x , c'). We have to show 
that c G [Ai • • • Ai-i ' C]- We will show by induction on the size of A' x ■ ■ ■ A' n _ x , where 
ai£ A'tC Ai for all i, that c G [ A x • • • A! n _ 1 ■ C]. 

For the base of the induction, if A[---A' n _ 1 is a singleton, then A\ = {ai} and by 
Lemma [3.2| , remembering that in this case r coincides with d, we find c G [A^ • ■ ■ A' n _ l ■ C]. 
Otherwise, i.e. if not all A\ are singletons, we may choose for each i an a[ G A\ such that 
a- ^ Oj if ^ {ctj}. Since A' x - ■ ■ A' n _ x is not a singleton, at least one of the set inequalities 
holds and (a' x , ■ ■ ■ , a' n _ x ) 7^ (ai, • • • , a„_i). 

Let be the patch to A' 1 ---A' n _ 1 from " ' { a n-i}- F° r & 11 * 

we have, by definition of the patch, | B\ • • • B l n _ x \ <\ A' x ■ ■ ■ A' n _ l |. By choice of 
a'i, (a x , ■ ■ ■ , a n -i) G B\ • • ■ B\_ x for all % and hence by the induction hypothesis, 
c G [B\ ■ ■ ■ B l n _ x ■ C). Assume now that c G" [A' x ■ ■ ■ A' n _ x ■ C], then by Property |a| of Def- 
inition |3l^, (a'i, a' n _ x , C)R(A[, A' n _^ C). There is some d G [a[ ■ ■ ■ o! n _ x ■ C] and by 



Definition ^]8| part |j, (af x , a^_i, c')R{a' x , a^_ l5 C). Also, by Definition |3]^ part |T|, 
(A[, A„_!, C)R(ai, a n _i, c). 

We have established that (a[, a' n _ x , d)R*(ai, a„_i, c) so by our original assump- 
tion we have c?(a^, o^_ l3 c') = d(ai, a n _i, c). By Equation || this implies also 
(a x , a n _i, c)i?*(a^, a^_ l5 c/) and hence (ai, a n _i, c)i?*(A l5 v4^_ 1; C). But then 
by Conditions ^| and |I] of Theorem we get c G [A^ • • ■ A' n _ x ■ C] which is a contradic- 



tion. We conclude that the right hand side of Equation g is a subset of the left hand 
side. 
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For the converse assume that c G C is such that for all ai, ...,a„_i (a$ G Aj), there exist 
a' l5 a^_ : and c' G C such that c ^ d and r(ai, a n _i, c) ^ r(a' 1; a^_ l5 c'). We need 
to prove that c G" [Ai ■ • ■ A n _ x ■ C]. Since X is finite, we may change the order of quantifiers 
in the assumption to 

3a[, ...,(x n _ x ,c G C,Vai, ...,a n _i, r(ai, ...,a n _i,c) ^ r(a' 1 , a^, c') 

Note that r(a u a„_i, c) ^ r(a[, c') -i(a x , a n _i, c)i2*(ai, <_ 1; c'). 
As above, but switching the roles of a« with those of let A' X) A n _ x be such that 
d'i^A^C Ai, and prove by induction on | A[ • • • A' n _ x |, i.e. the cardinality of A[ ■ • • A^_ x , 
that c G" [A[ ■ ■ ■ A'n^ ■ C]. If A[ - ■ ■ A' n _ x is a singleton, then = {a-}, and by Lemma |3~2] 
c G" [A^ • • ■ A' n _ x ■ G\. Otherwise choose for each % an G A- with 7^ if possible, 
and let {B\ ■ ■ ■ B % n _ x } be the patch to A' x • • • A' n _ x from {ai} ■ • • {a n _i}. Again we have for 
all i, (a[, ■ ■ • , a' n _ x ) G B\ ■ ■ ■ B l n _ x and | B\ ■ ■ ■ B l n _ x |<| A' x • ■ ■ A' n _ x | and hence by induction 
c Uj-^i " " " ' C]- Now if c G [A' x ■ ■ ■ A' n _ x ■ C] we get two consequences. First, by 
Definition JT8|, part (ai, a n _i, C)R(A' X , C). By the same definition, part |T|, 
we have (A' x , A' n _ x , C)R(a[, a' n _ x , c'). Second, from condition || of Theorem we 
derive cG [a\ ■ • ■ a n _i • C] so that (ai, a n -ij c)R(ai, a n _i, C). The above together 
give us (ai, a„_i, c)R*(a' x , a' n _ x , c') which contradicts our assumption. We have thus 
shown the converse inclusion. | 

4 Conclusion 

Iterated updates, of central importance for AI, cannot be properly treated in the AGM 
framework, not because of the update vs. revision distinction as was thought by Katsuno- 
Mendelzon, but because of the identification of epistemic states with belief sets, identifi- 
cation accepted by Katsuno-Mendelzon. An ontology in which epistemic states are richer 
than belief sets yields a family of updates that satisfy the AGM assumptions. We have 
first proved in Section 2 several properties, which are intuitively appealing, and extend 
the AGM postulates. In Section 3, we have given a complete set of properties, which 
characterize our approach, and shown a representation theorem (Theorem 3.2). In sum- 
mary, we have - on the philosophical side - introduced a natural and intuitively interesting 
ontology for iterated update, and - on the mathematical side - characterized our idea with 
a set of sound and complete conditions. 
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